Skip to main content
Log in

Requirements Reuse for Improving Information Systems Security: A Practitioner’s Approach

  • Original Article
  • Published:
Requirements Engineering Aims and scope Submit manuscript

Information systems security issues have usually been considered only after the system has been developed completely, and rarely during its design, coding, testing or deployment. However, the advisability of considering security from the very beginning of the system development has recently begun to be appreciated, and in particular in the system requirements specification phase. We present a practical method to elicit and specify the system and software requirements, including a repository containing reusable requirements, a spiral process model, and a set of requirements documents templates. In this paper, this method is focused on the security of information systems and, thus, the reusable requirements repository contains all the requirements taken from MAGERIT, the Spanish public administration risk analysis and management method, which conforms to ISO 15408, Common Criteria Framework. Any information system including these security requirements must therefore pass a risk analysis and management study performed with MAGERIT. The requirements specification templates are hierarchically structured and are based on IEEE standards. Finally, we show a case study in a system of our regional administration aimed at managing state subsidies.

This is a preview of subscription content, log in via an institution to check access.

Access this article

Price excludes VAT (USA)
Tax calculation will be finalised during checkout.

Instant access to the full article PDF.

Similar content being viewed by others

Author information

Authors and Affiliations

Authors

Rights and permissions

Reprints and permissions

About this article

Cite this article

Toval, A., Nicolás, J., Moros, B. et al. Requirements Reuse for Improving Information Systems Security: A Practitioner’s Approach. Requirements Eng 6, 205–219 (2002). https://doi.org/10.1007/PL00010360

Download citation

  • Issue Date:

  • DOI: https://doi.org/10.1007/PL00010360

Navigation